Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 11.0.0Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.90Upgrade Apache Tomcat to 10.1.25 | Nov 7, 2024 | Nov 7, 2024 |
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Jan 21, 2026 | Jan 20, 2026 |
| Debian | — | Upgrade tomcat10Upgrade tomcat9 | Sep 25, 2024 | Sep 25, 2024 |
| Redhat_linux | — | Upgrade tomcat-docs-webappUpgrade jss-debugsourceUpgrade tomcat-servlet-4.0-apiUpgrade idm-pki-toolsUpgrade jakarta-commons-httpclientUpgrade pki-core-debugsourceUpgrade xsomUpgrade glassfish-fastinfosetUpgrade tomcat-el-3.0-apiUpgrade apache-commons-collectionsUpgrade tomcatUpgrade jss-javadocUpgrade xmlstreambufferUpgrade jss-debuginfoUpgrade glassfish-jaxb-runtimeUpgrade idm-pki-symkeyUpgrade ldapjdkUpgrade xalan-j2Upgrade glassfish-jaxb-coreUpgrade python3-nssNo solution existsUpgrade tomcat-webappsUpgrade pki-servlet-4.0-apiUpgrade pki-core-debuginfoUpgrade javassistUpgrade glassfish-jaxb-txw2Upgrade idm-pki-baseUpgrade idm-pki-caUpgrade javassist-javadocUpgrade ldapjdk-javadocUpgrade xml-commons-resolverUpgrade idm-pki-serverUpgrade apache-commons-netUpgrade python3-nss-debuginfoUpgrade xerces-j2Upgrade apache-commons-langUpgrade resteasyUpgrade jackson-jaxrs-providersUpgrade tomcat-libUpgrade python3-idm-pkiUpgrade jackson-coreUpgrade bea-stax-apiUpgrade python-nss-docUpgrade tomcat-jsp-2.3-apiUpgrade idm-pki-acmeUpgrade glassfish-jaxb-apiUpgrade velocityUpgrade tomcatjssUpgrade stax-exUpgrade jackson-databindUpgrade slf4j-jdk14Upgrade jackson-annotationsUpgrade idm-pki-tools-debuginfoUpgrade jackson-jaxrs-json-providerUpgrade idm-pki-symkey-debuginfoUpgrade jssUpgrade jackson-module-jaxb-annotationsUpgrade idm-pki-kraUpgrade xml-commons-apisUpgrade slf4jUpgrade pki-servlet-engineUpgrade tomcat-admin-webappsUpgrade python-nss-debugsourceUpgrade relaxngDatatypeUpgrade idm-pki-base-java | Oct 31, 2024 | Sep 23, 2024 |
| Suse | — | Upgrade tomcat-el-3_0-apiUpgrade tomcat-webappsUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcatUpgrade tomcat-javadoc | Dec 5, 2025 | Oct 2, 2024 |
| Ubuntu | — | Upgrade libtomcat9-java (Ubuntu Pro)Upgrade tomcat10 (Ubuntu Pro)Upgrade libtomcat8-java (Ubuntu Pro)Upgrade libtomcat9-javaUpgrade libtomcat10-java (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade tomcat9 (Ubuntu Pro) | Jun 11, 2025 | Nov 7, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub